Privacy Notice for Home Delivery Service Patients

Privacy Notice for Home Delivery Service Patients

The purpose of this notice is to make you aware of how personal information about you is collected, created, shared and used for the purposes of the Home Delivery Service, both during and after your relationship with us.

Unipart Group Limited (company number 576777) operates the NHS Supply Chain Continence Home Delivery Service on behalf of Supply Chain Coordination Limited (SCCL) and has been given your personal information by your local healthcare provider (typically your local NHS Trust) in order to provide you with this Home Delivery Service.

In this notice we sometimes refer to NHS Supply Chain, supply chain, and supply chain members. This refers to third parties, besides your local healthcare provider, SCCL and Unipart, who use your personal information in order to provide the Home Delivery Service. They include organisations that SCCL and Unipart Group Limited delegate to for the purposes of providing the Home Delivery Service, and other supporting organisations such as IT and telecommunications service providers. Supply chain members include Movianto (to which Unipart has delegated responsibility for providing delivery and related services), and DXC (which manages the IT systems that SCCL provides for you and your local healthcare provider to participate in the Home Delivery Service electronically).

It is important that you and we try to ensure the personal information we hold about you is accurate and current. Therefore, please keep your local healthcare provider informed if your personal information changes (such as address, contact details, etc).

Who this notice is for ('you')

This Privacy Notice is for patients who receive prescribed continence products via the Home Delivery Service. It is also for the people who help such patients and who are involved in ordering or taking delivery of pads on behalf of such patients, such as care home staff, and trusted family, friends and neighbours.

Your data controller

Your data controller is any organisation that controls what your personal data is used for. For the Home Delivery Service, your data controller is your local healthcare provider, which orders the products that you require from the Home Delivery Service.

You can contact your local healthcare provider about your personal information in the same ways that you normally deal with them, such as by visiting in person, writing a letter or email to their published contact addresses, or calling them using their published phone numbers. If you want to contact them about your personal information you should ask for their Data Protection Officer (if your healthcare provider has one) or a member of their Information Governance team. A list of URL addresses for all local healthcare providers can be found in the annex to this notice to assist you in locating the privacy notice of your provider where you can find relevant contact details.

Unipart Group Limited, SCCL and the organisations who help them to provide the Home Delivery Service are each data processors. You should contact your local healthcare provider, not the data processors, about how your personal information is used. If there is something that the data processors need to know about processing your personal information, your local healthcare provider can tell them.

The kinds of personal information we collect, create and use about you

Information about you that is needed for the purposes of the Home Delivery Service is first collected when your local healthcare provider (such as your local NHS Trust or a member of their healthcare or authorised administrative staff, or your care home) places an order with NHS Supply Chain to provide a continence home delivery service to you.

Your healthcare provider will set you up as a service user within the Home Delivery Service, and will place the orders for you, using information that it already holds about you, typically being the following information:

  • personal contact details such as your title, name, home address, delivery address;
  • other contact details i.e. contact telephone numbers and email addresses, by which you or those who assist you can be contacted;
  • emergency details, i.e. next of kin;
  • Identifier: patient identifier assigned to you by your healthcare provider, which may include your NHS number;
  • service duration, i.e. how long the Home Delivery Service will be provided for you;
  • correspondence and electronic system usage data, i.e. information about letters, emails and calls by you (or on your behalf, or relating to you), information qualifying usage and use by you (or on your behalf) of your healthcare provider’s information and communications systems; and
  • order-specific instructions, your healthcare provider also has the opportunity to include order-specific instructions for Unipart Group Limited and its supply chain, but your healthcare provider is asked to ensure that these instructions do not include your name or contact details (or otherwise identify you).

Under UK data protection laws, certain categories of your personal information, referred to as 'special categories of data', are subject to special rules. The following special categories of data about you are collected, created and used for the Home Delivery Service:

  • information about your health, including your prescribed continence products, the health reasons why the product(s) are needed, and how frequently deliveries are required.

Unipart Group Limited and its supply chain will also create certain personal information about you so that they can operate the Home Delivery Service:

  • customer and order identifiers (e.g. reference numbers) assigned to you and to your orders, so that your orders can be tracked and processed through the supply chain;
  • correspondence and electronic system usage data, i.e. information about letters, emails and calls by you (or on your behalf, or relating to you), and use by you (or on your behalf) of information and communications systems operated or used by SCCL, Unipart Group Limited, and their supply chain members, including the Home Delivery telephone service and online portal;
  • your personal identification number (PIN), which is used by Unipart Group Limited and its supply chain members, and that allows you to use Home Delivery Service telephone self-service; and
  • the receipt signature that you (or the person who accepts delivery for you) gives electronically, when you confirm a delivery with each driver whom makes Home Delivery Service deliveries.

Changes to Home Delivery Service, and your personal information

From time to time the way that Home Delivery Service is operated may change. For example, the appointment of Unipart Group Limited (and its supply chain) may change, and SCCL itself might change. There was a change from NHS Business Services Authority to SCCL in 2018, and a change from DHL to Unipart Group Limited in 2019, and there will be other changes going forwards.

When this kind of underlying change happens, we need to transfer your personal information from the old service providers and IT systems and into the new ones who will operate the Home Delivery Service going forwards. Your personal information will be used for set-up and testing (so the old organisations and the new ones can plan and test in an effort to make the changes happen smoothly) in preparation for the changes.

What choices do you have about what personal information we use?

The following information is the minimum that is required for your order as part of the Home Delivery Service:

  • your personal contact details, so deliveries can be made to you;
  • in some cases, your NHS number, for invoice and payment administration between your local healthcare provider SCCL, Unipart Group Limited and the supply chain;
  • the service duration;
  • your correspondence and electronic usage information, which will be collected automatically, when you send correspondence, make calls or use electronic systems in relation to the Home Delivery Service, by the organisation that receives the correspondence/ calls or operates or uses the electronic systems;
  • customer and order identifiers and PINs (which are generated automatically);
  • information about your health; and
  • in some cases, a receipt signature (which is required to validate deliveries).

If you do not provide additional personal information, it will have an impact on the Home Delivery Service in some circumstances. For example, if we do not have alternative contact details for you or someone who helps you, we may not be able to notify you about delivery difficulties, make alternative delivery arrangements, or promptly resolve administrative questions or problems.

How do you withhold information from the Home Delivery Service?

You can give instructions to your local healthcare provider, asking them only to input the minimum personal information required (as described above) in the electronic ordering systems provided by SCCL, Unipart Group Limited and their supply chain as part of Home Delivery Service.

Purposes for which your personal information is used

Your personal information will be used for providing the Home Delivery Service for you and your local healthcare provider. The reason we process your data (known as the legal basis) is because we provide a service to you that is in the public interest, namely delivering healthcare products to you Your personal information will be used to:

  • organise and deliver your prescribed continence product(s) to the delivery address that you provide;
  • provide a service to you, including:
    allowing you (or someone on your behalf) to activate a scheduled delivery by telephone self-service;
    progressing and responding to queries and feedback from you (or someone on your behalf) or relating to you;
    keep you updated about changes to the Home Delivery Service that may affect you;
    where applicable, for example as part of a promotion, providing product samples requested by your healthcare provider;
  • raising, administering and paying invoices relating to orders and deliveries relating to you;
  • managing service performance and quality, including regular performance reporting by and reviews of supply chain members, dealing with complaints and exceptional matters;
  • automated logging and occasional audit of how your personal information is used for Home Delivery Service by supply chain members;
  • taking legal or administrative action in relation to orders and deliveries relating to you (legal basis: establishing, exercising or defending legal claims);
  • providing you with marketing information about new products and/or new services within the Home Delivery Service (legal basis: your explicit consent given to your local healthcare provider directly, or via the Home Delivery Service telephone service or online portal, or via Unipart Group Limited or other supply chain members);
  • ensuring that features and content from the Home Delivery Service online portal are available for you (if you choose them) and are presented in the most effective manner for you and your devices, using cookies or similar technology (legal basis: your explicit consent given to your local healthcare provider directly, or via the Home Delivery Service telephone service or online portal, or via Unipart Group Limited or other supply chain members);
  • providing reports to your local healthcare provider about how the Home Delivery Service is performing (this can include use of your gender and date of birth as your local healthcare provider may need to report on product types and age of their patients).

Your personal information will also be used for other purposes where the law requires or allows, including for other purposes that are compatible with the ones described above.

Your personal information may also be used by your local healthcare provider, SCCL and its supply chain where necessary to protect your interests (or someone else's interest), or where it is required in the public interest or for an official purpose other than those referred to above.

Please note that we may process your personal information without your knowledge or consent where this is required or permitted by law.

Your personal information will be shared within the supply chain for the Home Delivery Service, as described below. It will not be shared, by SCCL or its supply chain members, with third parties for the third parties' marketing purposes.

How your special categories of data are used

Special categories of data about you may be used for any of the above purposes. That is because the Home Delivery Service relates to your healthcare, and personal information about your health is one of the special categories of data.

Special categories of data about your race or ethnicity (where available) will also be provided to your local healthcare provider as part of the Home Delivery Service so that the provider has demographic data about its patients.

Automated decision-making

In some cases, personal data relating to you is created automatically as part of the Home Delivery Service, e.g. automatically generated identification numbers, and automatic logging. However, we do not envisage that any decisions will be taken about you using automated means. Your local healthcare provider or a member of the Home Delivery Service supply chain (on behalf of your provider) will notify you in writing if this position changes.

Data sharing

The Home Delivery Service is provided by SCCL and its supply chain members. Your personal information described in this notice will be shared with each supply chain member (and in particular, with SCCL itself, DXC which operates certain IT and phone systems for the Home Delivery Service, Unipart Group Limited and Movianto) to the extent they need access to the information in order to provide the Home Delivery Service.

Each supply chain member may also have to share your personal information with other third parties, for example where it is required by law, or where it is necessary to provide you and your healthcare provider with the Home Delivery Service. Third parties may include:

  • any employee within SCCL, Unipart Group Limited, and their and other supply chain members' organisations and group of companies;
  • contractors retained by SCCL, Unipart Group Limited and their supply chain members;
  • banks and other payment processing service providers who process payments relating to the Home Delivery Service;
  • IT service providers who maintain, improve, manage, optimise or fix the IT and phone systems used or relied on by SCCL, Unipart Group Limited and their supply chain members;
  • professional service providers, such as accountants, auditors, legal advisers and insurance brokers, who are used or relied on by SCCL, Unipart Group Limited and their supply chain members;
  • UK public authorities who have jurisdiction over SCCL, Unipart Group Limited and their supply chain members;
  • any third party organisations or companies in the event that SCCL, Unipart Group Limited or any of their supply chain members goes through a business change, such as a merger, being acquired by another person or company, or selling a portion of its assets that are used for Home Delivery Service; and
  • any third party organisations or companies that replace SCCL, Unipart Group Limited or any of their supply chain members and take over the operation of the Home Delivery Service or any part of it.

Your personal information may also be disclosed to other third parties if SCCL, Unipart Group Limited or any of their supply chain members have lawful grounds to do so, or are under a legal obligation to disclose or share it with them, or in order to establish, exercise or defend their legal rights or to protect the rights or safety of their organisations or staff.

Where your personal information is used

SCCL, Unipart Group Limited and Movianto do not intend to transfer your personal information outside the United Kingdom, and do not intend to permit their supply chain members to transfer your personal information outside the United Kingdom.

Data retention

Your personal information will be retained by SCCL, Unipart Group Limited and Movianto only for as long as necessary to fulfil the purposes of the Home Delivery Service, including for the purposes of satisfying any legal, accounting, or reporting requirements.

Your rights relating to personal information

It is important that the personal information used about you for the Home Delivery Service is reasonably up to date and accurate. Please tell us if your personal information changes during the period in which you use the Home Delivery Service. You should provide updates to your local healthcare provider.

Under certain circumstances, by law you have the following rights, which you can exercise by contacting your local healthcare provider (and the provider can tell SCCL, Unipart Group Limited and their supply chain about it):

  • Request access to your personal information (commonly known as a 'subject access request'). This enables you to receive a copy of the personal information held about you for the purposes of the Home Delivery Service, and to check that it is being used lawfully.
  • Request correction of the personal information that is held about you for the purposes of the Home Delivery Service.
  • Request erasure of the personal information that is held about you for the purposes of the Home Delivery Service. Where the right applies, it will enable you to ask your local healthcare provider to delete or remove personal information where there is no good reason for it to continue to be used for the Home Delivery Service. However, where erasure is requested, it may need the service to be terminated if the minimum information requirements cannot be met.
  • Request the restriction of use of your personal information for the purposes of the Home Delivery Service. Where the right applies, it will enable you to ask for certain uses of your personal information to be suspended, for example if you want us to establish its accuracy or to confirm the legal basis for it being used for the purposes of the Home Delivery Service. However, where restriction is requested, it may need the service to be suspended until the restriction is lifted.
  • Object to processing where the legal basis stated in this notice is performance of a task in the public interest, and also where your personal information is used for marketing purposes, you may have the right to object to that use of your personal information.
  • Withdraw consent where the legal basis for using your personal information is consent, you have the right to withdraw your consent at any time.
  • Request the transfer of your personal information from the Home Delivery Service online portal to another party, for them to provide a service similar to Home Delivery Service.

You will not normally have to pay a fee to access your personal information, or to exercise any of the other rights. However, we may charge a reasonable fee if your request for access is unfounded or excessive, and in other circumstances where the law allows for a fee to be charged. In some circumstances, your local healthcare provider, SCCL, Unipart Group Limited, Movianto and their supply chains may be entitled to refuse to comply with certain requests.

What you may need to provide to exercise rights

You may be asked to provide specific information to confirm your identity and to confirm whether or not you are entitled to exercise rights. These are appropriate security measures to ensure that the personal information is not disclosed to someone who is not entitled to receive it, and to ensure that information or its use is not modified on the instructions of someone who is not entitled to give such instructions.

Right to complain to the Information Commissioner

You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection and privacy, at any time.

Changes to this privacy notice

This notice may be updated at any time. If there is a major update you will be informed by your local healthcare provider, or (on behalf of your provider) by SCCL, Unipart Group Limited, Movianto or their supply chain members.

Notice date: February 2019 (version 1).

ANNEX – URL addresses for healthcare provider privacy statements

NHS Supply Chain Serviced Provider Name Privacy Notices (URL addresses)
2gether NHS Foundation Trust https://www.2gether.nhs.uk/privacy-notice/
Alder Hey Children's NHS Foundation Trust https://alderhey.nhs.uk/extra-links/privacy-policy-how-we-look-after-your-records
Anglian Community Enterprises https://www.acecic.co.uk/privacy-policy/
Blackpool Teaching Hospitals NHS Foundation Trust https://www.bfwh.nhs.uk/privacy-notice-for-our-service-users/
Bolton NHS Foundation Trust http://www.boltonft.nhs.uk/privacy-policy/
Bradford District Care NHS Foundation Trust No policy located
Bradford Teaching Hospitals NHS Foundation Trust https://www.bradfordhospitals.nhs.uk/privacy-statement/
Care Plus Group https://www.careplusgroup.org/about/privacy-policy/
Central and North West London NHS Foundation Trust https://www.cnwl.nhs.uk/home/privacy-policy/
Central London Community Healthcare NHS Trust https://www.clch.nhs.uk/about-us/clchs-privacy-statement
Cheshire and Wirral Partnership NHS Foundation Trust http://www.cwp.nhs.uk/about-us/privacy-notice/
City Healthcare Partnership CIC https://www.chcpcic.org.uk/pages/your-information-and-how-we-use-it
County Durham and Darlington NHS Foundation Trust https://www.cddft.nhs.uk/privacy-statement.aspx
East Lancashire Hospitals NHS Trust https://elht.nhs.uk/about-us/privacy-policy-and-cookie-policy
East London NHS Foundation Trust https://www.elft.nhs.uk/About-Us/Privacy-and-Your-Data
Essex Partnership University NHS Foundation Trust https://eput.nhs.uk/privacy-policy/
Gloucestershire Hospitals NHS Foundation Trust https://www.gloshospitals.nhs.uk/privacy-notice/
Guy's and St Thomas' NHS Foundation Trust No policy located
Harrogate and District NHS Foundation Trust https://www.hdft.nhs.uk/privacy-notices/patients-privacy-notice/
Homerton University Hospital NHS Foundation Trust http://www.homerton.nhs.uk/media/102291/privacy_notice.pdf
Hounslow and Richmond Community Healthcare NHS Trust http://www.hrch.nhs.uk/privacy-policy/
Humber NHS Foundation Trust https://www.humber.nhs.uk/data-protection.htm
Lancashire Care NHS Foundation Trust https://www.lancashirecare.nhs.uk/privacy-notice
Lancaster House Consulting, Diagnostics & Surgical Ltd No policy located
Leeds Community Healthcare NHS Trust No policy located
Leicester Partnership NHS Trust https://www.leicspart.nhs.uk/_Aboutus-Whatwedowithyourinformationprivacynotice.aspx
Mersey Care NHS Foundation Trust https://www.merseycare.nhs.uk/about-us/privacy-notice/
NHS Airedale, Wharfedale and Craven CCG http://www.airedalewharfedalecravenccg.nhs.uk/worth-knowing/privacy-information-notice-how-your-information-is-used/
NHS Oldham Clinical Commissioning Group http://www.oldhamccg.nhs.uk/Portals/0/Docs/Policies/FOI%20policy%20amended%20April%202015.pdf
NHS Scarborough and Ryedale CCG http://www.scarboroughryedaleccg.nhs.uk/how-your-personal-information-is-used-by-nhs-scarborough-and-ryedale-ccg-privacy-notice/
NHS Vale of York CCG https://www.valeofyorkccg.nhs.uk/privacy
North East London NHS Foundation Trust No policy located
North Tees and Hartlepool Hospitals NHS Foundation Trust https://www.nth.nhs.uk/support/privacy/
Northamptonshire Healthcare NHS Foundation Trust https://www.nhft.nhs.uk/privacy
Oxford Health NHS Foundation Trust https://www.oxfordhealth.nhs.uk/privacy/
Oxleas NHS Foundation Trust http://oxleas.nhs.uk/privacy-policy/
Pennine Acute Hospitals NHS Trust https://www.pat.nhs.uk/patients-and-visitors/patient-privacy-notice-how-we-use-share-and-protect-your-personal-information.htm
Pennine Care NHS Foundation Trust https://www.penninecare.nhs.uk/about-us/accessing-information/data-protection-and-confidentiality/
Salford Royal NHS Foundation Trust http://www.srft.nhs.uk/for-patients/information/
Sheffield Teaching Hospitals NHS Foundation Trust https://www.sth.nhs.uk/about-us/general-data-protection-regulations
Shropshire Community Health NHS Trust https://www.shropscommunityhealth.nhs.uk/content/doclib/10648.pdf
South Tees Hospitals NHS Foundation Trust https://www.southtees.nhs.uk/privacy/
South West Yorkshire Partnership NHS Foundation Trust https://www.southwestyorkshire.nhs.uk/privacy-policy/
St George's University Hospitals NHS Foundation Trust https://www.stgeorges.nhs.uk/about/privacy-notice/
The Mid Yorkshire Hospitals NHS Trust https://www.midyorks.nhs.uk/privacy-policy
Virgin Care https://www.virgincare.co.uk/legal-information/privacy-policy/
Whittington Health NHS Trust No policy located
Worcestershire Health and Care NHS Trust https://www.hacw.nhs.uk/privacy-statement/
York Teaching Hospitals NHS Foundation Trust https://www.yorkhospitals.nhs.uk/seecmsfile/?id=3242
Your Healthcare CIC http://www.yourhealthcare.org/privacy-policy/